CVE-2022-48730
published 2024-06-20CVE-2022-48730: In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix potential spectre v1 gadget It appears like nr could be a Spectre v1…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.26%
17.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
dma-buf: heaps: Fix potential spectre v1 gadget
It appears like nr could be a Spectre v1 gadget as it's supplied by a
user and used as an array index. Prevent the contents
of kernel memory from being leaked to userspace via speculative
execution by using array_index_nospec.
[sumits: added fixes and cc: stable tags]
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.10-1 (bookworm) | linux 5.16.10-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= c02a81fba74fe3488ad6b08bfb5a1329005418f8 < 5d40f1bdad3dd1a177f21a90ad4353c1ed40ba3a | 5d40f1bdad3dd1a177f21a90ad4353c1ed40ba3a |
| linux | linux | >= c02a81fba74fe3488ad6b08bfb5a1329005418f8 < 24f8e12d965b24f8aea762589e0e9fe2025c005e | 24f8e12d965b24f8aea762589e0e9fe2025c005e |
| linux | linux | >= c02a81fba74fe3488ad6b08bfb5a1329005418f8 < cc8f7940d9c2d45f67b3d1a2f2b7a829ca561bed | cc8f7940d9c2d45f67b3d1a2f2b7a829ca561bed |
| linux | linux | >= c02a81fba74fe3488ad6b08bfb5a1329005418f8 < 92c4cfaee6872038563c5b6f2e8e613f9d84d47d | 92c4cfaee6872038563c5b6f2e8e613f9d84d47d |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.103-1 | 5.10.103-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 5.11 < 5.15.22 | 5.15.22 |
| linux | linux_kernel | >= 5.16 < 5.16.8 | 5.16.8 |
| linux | linux_kernel | >= 5.6 < 5.10.99 | 5.10.99 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: dma-buf: heaps: Fix potential spectre v1 gadget
vendor_redhat·2024-06-20·CVSS 5.5
CVE-2022-48730 [MEDIUM] CWE-402 kernel: dma-buf: heaps: Fix potential spectre v1 gadget
kernel: dma-buf: heaps: Fix potential spectre v1 gadget
In the Linux kernel, the following vulnerability has been resolved:
dma-buf: heaps: Fix potential spectre v1 gadget
It appears like nr could be a Spectre v1 gadget as it's supplied by a
user and used as an array index. Prevent the contents
of kernel memory from being leaked to userspace via speculative
execution by using array_index_nospec.
[sumits: added fixes and cc: stable tags]
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
Package: kernel (Red Hat Enterprise Linux 9) - Not aff
Debian
CVE-2022-48730: linux - In the Linux kernel, the following vulnerability has been resolved: dma-buf: he...
vendor_debian·2022·CVSS 5.5
CVE-2022-48730 [MEDIUM] CVE-2022-48730: linux - In the Linux kernel, the following vulnerability has been resolved: dma-buf: he...
In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix potential spectre v1 gadget It appears like nr could be a Spectre v1 gadget as it's supplied by a user and used as an array index. Prevent the contents of kernel memory from being leaked to userspace via speculative execution by using array_index_nospec. [sumits: added fixes and cc: stable tags]
Scope: local
bookworm: resolved (fixed in 5.16.10-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.10-1)
sid: resolved (fixed in 5.16.10-1)
trixie: resolved (fixed in 5.16.10-1)
GHSA
GHSA-88rc-96xj-2mvh: In the Linux kernel, the following vulnerability has been resolved:
dma-buf: heaps: Fix potential spectre v1 gadget
It appears like nr could be a Sp
ghsa_unreviewed·2024-06-20
CVE-2022-48730 [MEDIUM] CWE-203 GHSA-88rc-96xj-2mvh: In the Linux kernel, the following vulnerability has been resolved:
dma-buf: heaps: Fix potential spectre v1 gadget
It appears like nr could be a Sp
In the Linux kernel, the following vulnerability has been resolved:
dma-buf: heaps: Fix potential spectre v1 gadget
It appears like nr could be a Spectre v1 gadget as it's supplied by a
user and used as an array index. Prevent the contents
of kernel memory from being leaked to userspace via speculative
execution by using array_index_nospec.
[sumits: added fixes and cc: stable tags]
OSV
CVE-2022-48730: In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix potential spectre v1 gadget It appears like nr could be a Spec
osv·2024-06-20·CVSS 5.5
CVE-2022-48730 [MEDIUM] CVE-2022-48730: In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix potential spectre v1 gadget It appears like nr could be a Spec
In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix potential spectre v1 gadget It appears like nr could be a Spectre v1 gadget as it's supplied by a user and used as an array index. Prevent the contents of kernel memory from being leaked to userspace via speculative execution by using array_index_nospec. [sumits: added fixes and cc: stable tags]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/24f8e12d965b24f8aea762589e0e9fe2025c005ehttps://git.kernel.org/stable/c/5d40f1bdad3dd1a177f21a90ad4353c1ed40ba3ahttps://git.kernel.org/stable/c/92c4cfaee6872038563c5b6f2e8e613f9d84d47dhttps://git.kernel.org/stable/c/cc8f7940d9c2d45f67b3d1a2f2b7a829ca561bedhttps://git.kernel.org/stable/c/24f8e12d965b24f8aea762589e0e9fe2025c005ehttps://git.kernel.org/stable/c/5d40f1bdad3dd1a177f21a90ad4353c1ed40ba3ahttps://git.kernel.org/stable/c/92c4cfaee6872038563c5b6f2e8e613f9d84d47dhttps://git.kernel.org/stable/c/cc8f7940d9c2d45f67b3d1a2f2b7a829ca561bed
2024-06-20
Published